VoIP Tech Chat

Patrick and Fred Chat… sometimes about VoIP

Got Firefox? Upgrade to 3.6.2.

4 comments

Upgrade Me

If you’re running Firefox 3.6, Mozilla strongly recommends you update to version 3.6.2. The new version corrects a critical security hole allowing an attacker to crash your browser and/or run arbitrary code on your machine.

The Security Warning advises:

Mozilla Foundation Security Advisory 2010-08

Title: WOFF heap corruption due to integer overflow
Impact: Critical
Announced: March 22, 2010
Reporter: Evgeny Legerov
Products: Firefox 3.6

Fixed in: Firefox 3.6.2

DESCRIPTION

Security researcher Evgeny Legerov of Intevydis reported that the WOFF decoder contains an integer overflow in a font decompression routine. This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim’s browser and execute arbitrary code on his/her system.

Note: Support for the WOFF downloadable font format is new in Firefox 3.6 (Gecko 1.9.2); this vulnerability does not affect products built on earlier versions of the Mozilla browser engine.

REFERENCES

Firefox recommends that all users upgrade to version 3.6.2 to correct this issue. The product can be downloaded from their website or by using the Check for Updates feature of the software.

Written by Fred

March 23rd, 2010 at 7:16 am

Posted in tech

Tagged with ,

4 Responses to 'Got Firefox? Upgrade to 3.6.2.'

Subscribe to comments with RSS or TrackBack to 'Got Firefox? Upgrade to 3.6.2.'.

  1. [...] For more information, check out the post at VoIP Tech Chat. [...]

  2. blogged: Got Firefox? Upgrade to 3.6.2. http://bit.ly/alHW9G

    Fred Posner

    23 Mar 10 at 12:17 pm

  3. Updating FireFox right now! http://tr.im/T0l6

    mjgraves

    23 Mar 10 at 2:20 pm

  4. [...] update follows another critical security hole less than 2 weeks earlier. The product can be downloaded from their website or by using the Check [...]

Leave a Reply